Re: Is it dangerous to use a local administrator account for anonymous access to a sec
Web Server forum
Back To The Forum Home!Search!Private Messaging System

Web Server Talk Web Server Talk > Web Servers reviews > IIS server support > IIS Server Security > Re: Is it dangerous to use a local administrator account for anonymous access to a sec




  Last Thread   Next Thread Next
  Show Printable Version Email this Page Subscribe to this Thread      Post New Thread    Post A Reply      

    Re: Is it dangerous to use a local administrator account for anonymous access to a sec  
Ken Schaefer


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
04-17-07 06:18 AM

The issue here is that if anyone can, in any way, subvert the application,
then they will have complete control over the machine (for example via SQL
injection, cross-site scripting vulnerability, session replay attack etc).
From there, they will almost certainly be able to, eventually, subvert the
entire domain.

Cheers
Ken


"Paulaner" wrote in message
 news:lsu623hegv5tv144v6r4i50fgoqhsdjhr1@
4ax.com...
>
> We have a web application that uses asp pages and javascript to
> display information to users.  We want the data to be secure, so the
> login page will  redirect http:// users from port 80 to https://  on
> port 443.  We prompt for a username a password, then use an isapi
> filter to authenticate them with our database.
>
> The service team got a report about some trouble with this website, so
> they changed the anonymous account logon from IUSR_computername to a
> local user account in the administrators group.   This has fixed their
> problem, but I am concerned that they just opened a security hole.
>
> The only reference to this issue I can fine in technet is this
> comment:  "If you use an account other than IUSR_computername for
> anonymous access, choose the rights you assign to it very carefully. "
> from http://msdn2.microsoft.com/en-us/library/ms951775.aspx
>
> Can anyone point me to some documentation that says "don't do this",
> or give me some sufficient ammunition to convince them to undo this
> action and appropriately repair the root cause of their issue?






[ Post a follow-up to this message ]



    Sponsored Links  




 





   All times are GMT. The time now is 05:44 PM.      Post New Thread    Post A Reply      
  Last Thread   Next Thread Next


Most Popular forums 

Forum Jump:
Rate This Thread:

Forum Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is OFF
vB code is ON
Smilies are ON
[IMG] code is OFF
 
Medical and Health forum | Computer Games Reviews | Graphics design forum

Back To The Top
Home | Usercp | Faq | Register